fix(codegen/vercel): make create-only required fields optional in global args (swamp-club #2644) #428
Loading…
Reference in a new issue
No description provided.
Delete branch "2644"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Fixes swamp-club #2644.
Problem
Generated Vercel models marked every field that the create request requires as required in
GlobalArgsSchema. swamp checks that schema in full in two places:swamp model createwith any--global-arg;swamp workflow validate, for steps that name a model type rather than a definition.So a model set up for
get,lookuporsyncwas rejected unless callers passed placeholder create values. For example,@swamp/vercel/projects/envwith onlyidOrNameandnamefailed onkey,typeandvalue. As with Cloudflare (#2645), method runs validate with.partial(), sogeton an existing definition already worked. The issue's claim that read methods fail was not accurate.Triage also found a related bug. A resource property named
slugcollides with the injected teamslugarg, so it was silently dropped from the schema and every request body. Edge Config, feature flag and segment creates could never send their requiredslug, andedge-config/global-config's PUT update sent an empty body.Fix (Vercel codegen; mirrors the Cloudflare fix, PR 344)
createRequiredProperties, limited to defined properties and excluding parent path params. No resource property stays required; parent params and the syntheticnamedo..optional(), and the generatedcreatethrowscreate requires global arguments: <names>before any API call.updatethrowsupdate requires global arguments: <names>before the PUT if one is still missing. PATCH is unchanged.slugcollision: a resource property namedteamId,slugortokenis exposed asresource<Name>(for exampleresourceSlug) and mapped back to its API name in bodies, checks and lookup filters. The teamslugkeeps its meaning, so existing definitions are unaffected. This affects 5 models:edge-config/global-config,feature-flags/flags,feature-flags/segments,teams/teamsandenvironment/custom-environments.resourceSlugas removed and strip it from stored definitions. A test keeps the list in sync with the generated schema.scripts/check_upgrades.ts: the upgrade path test took a manifest on the merge base as proof of publication, but@swamp/vercel/dnsand@swamp/vercel/project-membershave been on main since 2026-08-03 and were never published. It now asksswamp extension info. An extension the registry reports as not found is skipped, as the conventions already promise. Any other registry failure still fails the gate, and stdout and stderr are parsed separately. Because this is a trust-root change,review-integritywill run.codegen/designs/vercel.mddocuments all of the above.Regeneration
deno task generate:vercelchanged exactly 27 of 30 models, each with one CalVer bump; a second run changed nothing.aliases,certsanddomainsare unchanged. 22 models get an identity upgrade entry and 5 getAdded: resourceSlug; none removes a field. This merge also publishesdnsandproject-membersfor the first time.Testing
codegen/vercel/globalArgs_integration_test.tsagainst aDeno.servemock: create fails with zero requests;resourceSluggoes in the body while teamslugstays in the query; the PUT fills from live, skips the GET when set, and fails before the PUT when the live resource lacks the field. A mutation check confirmed the tests fail without the checks.model createand a type-basedworkflow validateforprojects/envfail before and pass after. Create throws the check message without making any request.vercel-labs/emulate): the same scenario ran with the published@swamp/vercel/projectsand with this branch viaswamp extension source add. Results are identical except for the two intended changes: a scope-onlyenvdefinition is accepted, and its create stops with 0 env vars created. The emulator does not cover Edge Config, feature flags,/v1/teamsor custom environments, so theslugpaths are tested against mocks only.2026.10.01.1, and the 2 unpublished ones are skipped. verify-reviews: code, adversarial and CI security reviews pass with low findings only. The attestation is posted forc566e6850.Behaviour changes to be aware of
workflow validateno longer flags a create step that is missing create-required fields; the error appears at run time, still before any API call.swamp model type describeno longer marks those fields required.resourceSlug.🤖 Generated with Claude Code